Servomex logo
ServomexPosted 6 days ago

DevSecOps Engineer

$95,000–$130,000 year

HybridNiwot, Colorado, United States

Full TimeSenior LevelMediumIndustrial Services

Job Summary

Design, implement, and maintain secure cloud environments and CI/CD pipelines that integrate automated security testing, vulnerability management, and compliance controls. Collaborate with firmware and software teams to improve workflows, release strategies, and secure development practices using Infrastructure as Code and binary repository management. Manage software artifacts, third-party dependencies, and monitoring solutions while participating in the vulnerability management lifecycle for security incidents. Provide technical guidance, mentorship, and process evaluation to drive continuous improvement and secure software delivery. This role supports the development of micro-contamination monitoring equipment for semiconductor and pharmaceutical industries, requiring a hybrid schedule with on-site presence at least three days per week.

Required Qualifications

  • Bachelor of Science in Computer Science or related Engineering field
  • Proven experience as a DevSecOps Engineer, Security-Focused DevOps Engineer, or similar role
  • Development experience in either embedded firmware or software
  • Familiarity integrating SAST, DAST, SCA and SBOM tools into CI/CD pipelines
  • Hands-on experience working with binary repositories
  • Proficiency with AWS or other major cloud platforms
  • Proficiency in IaC and configuration management tools
  • Strong scripting skills in languages like Bash, Python, or PowerShell
  • Familiar with build tools such as CMake, Make, or custom toolchains
  • Experience with containerization technologies such as Docker
  • Working knowledge of CI/CD tools like Jenkins, Bitbucket Pipelines and GitHub Actions
  • Familiarity with Cyber Security practices including cybersecurity principles, vulnerability management, and DevSecOps practices
  • Familiarity with monitoring and logging tools such as Prometheus and Grafana
  • Excellent problem-solving and troubleshooting skills, with the ability to analyze complex systems and identify root causes
  • Working knowledge of shift-left principles and practices
  • Strong communication and collaboration skills, capable of working effectively within a team
  • Must be able to sit, stand, and use a computer for extended periods of time
  • Occasional lifting of up to 20 lbs.

Desired Qualifications

  • Understanding of Agile, DevOps and DevSecOps methodologies and their application in software development processes
  • Expertise in Git and the Atlassian suite of software development tools including Bitbucket pipelines
  • Experience integrating security scanning tools into CI/CD pipelines
  • Familiarity with software composition analysis (SCA) and open-source compliance practices
  • Familiarity with DORA metrics
  • Certifications in AWS, Cyber Security, or DevSecOps practices
  • Experience with SBOM standards such as SPDX and CycloneDX
  • Familiar with industry standards such as EN 18037 and IEC 62443
  • Knowledge of the EU Cyber Resilience Act
  • Experience in multi-disciplinary engineering environment

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce